>>21693767There's an even better example: OpenSSL
This is much smaller than systemd, and it's also a very critical library. Despite that, there was a bug in the wild (Heartbleed) that went unnoticed for 2 years. When it was discovered, the OpenSSL devs dragged their feet and refused to take any blame. It wasn't until the OpenBSD devs (an unrelated project) decided to fork that code into their own LibreSSL version that any fix was made. And to fix it, they had to tear the whole thing apart, because they couldn't be sure other bugs wouldn't remain. And this is much smaller codebase than systemd, by orders of magnitude!
So yeah, open source doesn't mean it's bug-free, even if it's a very sensitive piece of code. And that's why I don't trust any of this crypto shit. I mean besides the fact that it's an obvious scam to begin with. :D